Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

1 detection

Detects incoming HTTP requests to a FortiSandbox device that contain suspicious command injection patterns. The rule monitors both the URI and the request body for shell metacharacters such as ';', '|', '`', '$(', or '&&', followed by common binary execution commands (e.g., cat, wget, curl, bash, rm). This behavior is indicative of an exploit attempt targeting CVE-2026-39808.
avatar
Ankit Mehta@Secvyn
avatar
Detections.ai Community
6 days ago
000